Skip to content

The stack randomization feature in the Linux kernel...

Moderate severity Unreviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Feb 3, 2023

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.

References

Published by the National Vulnerability Database Mar 16, 2015
Published to the GitHub Advisory Database May 14, 2022
Last updated Feb 3, 2023

Severity

Moderate

EPSS score

1.081%
(85th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2015-1593

GHSA ID

GHSA-6qcg-g8hp-m564

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.